Latest / Story
What Is the Difference Between an Interim ATO and a Full ATO?
You finished your assessment, but the decision letter is not the clean authorization you expected.
Instead of a full ATO, you got conditions, restrictions, or a short authorization window. Here is what each outcome means and how to move past it.
"Interim ATO" is not a formal term
That phrase does not appear in NIST SP 800-37. NIST is the National Institute of Standards and Technology, and SP means Special Publication. RMF stands for Risk Management Framework. ATO stands for Authorization to Operate.
Appendix F of NIST SP 800-37 lists four authorization decisions. They are authorization to operate, common control authorization, authorization to use, and denial of authorization. (NIST SP 800-37 Rev. 2, Appendix F)
People say "interim ATO" for two different things. One is an ATO granted with conditions. The other is the Department of Defense (DoD) practice of an Interim Authorization to Test (IATT).
NIST handles the interim case inside the ATO itself. The authorizing official (AO) may grant a short authorization for live testing before all controls are in place. A footnote in the publication notes this was formerly called an interim authority to test. (NIST SP 800-37 Rev. 2, Appendix F)
What a full ATO means
"Full ATO" is shop talk, not a formal NIST term. It means the AO reviewed your authorization package and accepted the risk.
The package holds the security plan, the security assessment report, the POA&Ms, and the authorization decision document. POA&M stands for Plan of Action and Milestones. (DoDI 8510.01, July 19, 2022)
The system is authorized to operate for a set period under the AO's terms and conditions. The AO sets an authorization termination date (ATD). When that date arrives, the authorization expires and you must reauthorize. (NIST SP 800-37 Rev. 2, Appendix F)
A full ATO can still carry normal terms and conditions. The difference is that no extra remediation deadlines hang over it.
What an authorization with conditions means
This is still an ATO, but with strings attached.
Expect a short authorization period ending on the ATD. The AO can adjust that date at any time if concern about the system grows. (NIST SP 800-37 Rev. 2, Appendix F)
Expect operating restrictions. NIST gives examples of restrictions. They include limiting users, restricting run hours, and heavier logging, scanning, and monitoring. The system may also be limited to the functions that need live testing. (NIST SP 800-37 Rev. 2, Appendix F)
Expect remediation deadlines tied to your POA&M. Each open finding gets a fix and a milestone date. Missing them puts the authorization at risk.
Side by side: scope, duration, conditions, and who signs
| Full ATO | ATO with conditions | IATT (DoD practice) | |
|---|---|---|---|
| Scope | Production operation | Production operation with limits | Testing, not production |
| Duration | Set period ending on the ATD | Short period ending on an adjustable ATD | Limited to the testing effort |
| Conditions | Normal terms from the AO | Restrictions plus remediation deadlines | Testing-only limits |
| Who signs | The AO | The AO | The AO |
The AO decides from the authorization package in every case. The same AO can also rescind a decision if you violate its terms and conditions. (NIST SP 800-37 Rev. 2, Appendix F)
Where an IATT fits
In DoD, the IATT is a distinct authorization decision. DoDI 8510.01 names interim authorization to test alongside ATO, ATO with conditions, and denial ATO. (DoDI 8510.01, July 19, 2022)
Its name describes its purpose: testing in the live environment, not full operation. Outside DoD, say "ATO with conditions" instead of "interim ATO." That wording matches what NIST actually publishes.
What to do when you get conditions
Start with the authorization decision document. It states the decision, the terms and conditions, the ATD, and any events that trigger a review. (NIST SP 800-37 Rev. 2, Appendix F)
Map every condition to a POA&M item. Give each item an owner, a fix, and a milestone date.
Collect fresh evidence after each fix. Assessors test the live system, not old screenshots.
Track the ATD like a contract deadline. Reauthorization uses the same package you built before.
How to convert conditions into a full ATO
Close every POA&M item on schedule. Retest each remediated control and keep the evidence.
Update the security plan, the security assessment report, and the POA&Ms. The AO decides from the package, so a stale package stalls the decision.
Ask the AO to re-review and issue a new authorization decision. Authorization decision documents may be digitally signed. A new decision with no conditions is your full ATO. (NIST SP 800-37 Rev. 2, Appendix F)
Sources
- NIST SP 800-37 Rev. 2, Risk Management Framework for Information Systems and Organizations, Appendix F (Authorization Decisions): https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
- DoD Instruction 8510.01, "Risk Management Framework for DoD Systems," July 19, 2022: https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/851001p.pdf
Next step
Authorization packages are only as good as the evidence inside them. PolicyCortex uses 33 collectors that read live Azure configuration. It builds SSP (System Security Plan), SAR (Security Assessment Report), and POA&M output from the evidence it collects. See how it works.